Privacy Policy and Data Security
Effective date: July 15, 2026
Bizzy Marketplace ("Bizzy", "we", "us", or "our") provides a marketplace and workflow tools for people in the United States who are buying, selling, reviewing, or evaluating small businesses. This policy explains how we handle information when you visit Bizzy, create an account, list a business, message other users, report or block an account, sign or manage NDAs, configure external diligence links, manage buyer/deal workflow, or otherwise use the service.
Bizzy is intended for U.S. users and U.S. business transactions. We do not intentionally offer the service to users in the European Union, European Economic Area, or United Kingdom.
Information We Collect
- Account and profile information, such as name, username, avatar, roles, authentication details, passkey metadata, and account settings.
- Buyer and seller workflow information, such as buyer criteria, saved listings, seller profile fields, listing drafts, submitted listings, listing photos, seller-reported business details, listing-scoped buyer/contact workflow state and private seller/broker notes.
- Transaction and communication information, such as messages, notifications, account blocks, message reports and optional report details, immediate-danger selections, moderation case state and finite outcomes, NDA signatures, NDA access requests and decisions, seller-configured external diligence links, reviewer decisions, and Premium beta entitlement activity.
- Uploaded content is limited to profile photos and listing photos. Bizzy does not accept, host, download, scan, parse, or preview seller diligence files. Sellers may configure links to supported third-party providers.
- Usage, device, and security information, such as session data, IP address, browser details, request metadata, security logs, rate-limit events, and product analytics where enabled.
- Support, feedback, appeal, or administrative communications you choose to send to us.
How We Use Information
- Operate, secure, maintain, and improve Bizzy.
- Create and manage accounts, roles, authentication, passkeys, sessions, and account settings.
- Show marketplace listings, support listing review, route buyer and seller workflows, and provide Buyer Matches.
- Enable messages, notifications, account blocks, user reports, human moderation, NDA workflows, external diligence-link access, saved listings, matched-buyer messaging, buyer file workflow, private workflow notes, and access-decision audit records.
- Detect abuse, debug errors, enforce messaging and account limits, audit sensitive workflows, and protect users and the service.
- Measure product usage with privacy-bounded analytics when analytics is enabled and not opted out.
- Comply with legal obligations, resolve disputes, and enforce our Terms of Service.
Messaging, Reports, and Moderation
Messaging and NDA diligence access are separate. Starting a conversation does not sign an NDA or approve external-link access. Messages are shared with the other conversation participant and may be reviewed by an authorized human administrator when a participant reports a received message and an administrator holds the current moderation claim. The initial evidence view is bounded to the selected message and nearby shared context; explicit audited expansion remains capped at 50 messages per active claim.
Report queue rows, in-app moderation notifications, realtime notification events, analytics, and operational logs are designed not to contain message bodies or report details. Moderation audit records use finite codes and content-free references rather than copied message text. Bizzy has no AI/model/provider integration for message moderation in this release and does not send message or report content to an external model for automated decisions. Final moderation outcomes are authorized by human administrators.
Message bodies are normalized plain text at rest and rendered through ordinary text interpolation, not raw HTML. Unsent message drafts are stored only in browser session storage for the current account and tab, and are cleared on an observed account/session change.
Product Analytics
Bizzy may use PostHog for privacy-bounded product analytics. Analytics is designed around sanitized route templates, route areas, coarse buckets, and funnel events rather than private content.
Bizzy does not send message bodies, report details, private note bodies, internal decision notes, external diligence URLs, exact seller financials, listing prices, or budgets, buyer criteria details, private addresses, raw internal identifiers, usernames, emails, phone numbers, passkey credential details, cookies, auth headers, raw URLs, error messages, stack traces, or source maps to PostHog.
Signed-in users can opt out of account-level product analytics from Settings > Privacy. Opting out disables browser analytics, PostHog identify, and user-level server analytics for that signed-in account. It does not disable security, audit, operational, rate-limit, notification, messaging moderation, or legally required records kept outside PostHog.
How We Share Information
- With other users as needed for marketplace features, such as public listings, seller profile information, buyer-seller messages, NDA status, and seller-controlled external diligence-link metadata.
- With authorized administrators who need access to operate, review, support, moderate, or secure the service. Reviewers do not automatically receive message-moderation evidence access.
- With service providers that help us host, store, authenticate, analyze, deliver, monitor, or secure the service.
- When required by law, legal process, enforcement requests, fraud prevention, security investigations, or to protect rights, safety, users, or the service.
- In connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality or transfer protections.
Cookies, Sessions, and Similar Technologies
Bizzy uses cookies, local storage, session storage, and similar technologies for authentication, sessions, security, preferences, message drafts, passkey flows, and product functionality. When product analytics is enabled, analytics tooling may also use browser storage in a privacy-bounded way.
Listing Locations
Sellers can provide a specific business location while choosing a less precise public map display. Depending on the listing setting, buyers may see an exact public location, an approximate nearby pin, or a general city/market area.
Private location fields are used for listing management, review, and seller-controlled public display. They are not automatically shown as an exact public address unless the seller chooses exact public location.
Retention and Deletion
We keep information for as long as needed to provide the service, operate the marketplace, secure the product, meet legal obligations, resolve disputes, and enforce agreements. Some records, such as audit logs, NDA records, NDA access-decision records, security events, message reports and moderation records, billing or entitlement records, and legally required records, may be retained after account deletion when appropriate.
When an account deletion request is completed, deleting an account may not remove information already shared with other users, message/report evidence retained for safety or disputes, records we must keep for legal or security reasons, compact non-PII workflow or moderation audit metadata, or obligations that survive deletion, such as signed NDAs. Private seller/broker note bodies and direct external-contact details are deleted or anonymized where appropriate. See Account Deletion Requests for the current deletion-request process.
Archiving a conversation only changes the acting user's inbox visibility, and blocking stops communication between the account pair; neither action deletes shared history or automatically deletes a report.
Your Choices
- Update account profile and privacy settings from Settings.
- Opt out of account-level product analytics from Settings > Privacy.
- Archive a conversation for your inbox, block another conversation participant, or report a received message through the messaging safety controls.
- Control which listing details and location precision are shown publicly when creating or editing seller listings.
- Schedule account deletion from Settings, or use the support channels available in the product.
- Use browser controls to manage cookies and browser storage, understanding that some controls may affect sign-in, message-draft recovery, or core functionality.
Security
We use administrative, technical, and organizational safeguards designed to protect information, including encrypted transport, passkey-based authentication, access controls, NDA-gated external-link authorization, transaction-owned messaging checks, bounded moderation evidence, and workflow-specific authorization. No online service can guarantee perfect security.
Children
Bizzy is not intended for children or for anyone under 18. We do not knowingly collect personal information from children under 13.
Changes
We may update this Privacy Policy as Bizzy changes. The effective date shows when the policy was most recently revised. Material changes may also be surfaced in the product or through other reasonable notice.
Contact
For privacy questions or requests, contact us through the account, support, or administrative channels available in the product.
